This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Weekly Intelligence for a Digital World

INTELLIGENCE BRIEF // DECLASSIFIED

Briefing No. 105
September 22, 2026

THE $200 RECRUITMENT

First they paid for pictures. Then came the $25,000 offer.

A Note from Eric

Back in my day (yes, I know I’m aging myself here) spycraft was much more hands-on.

When I worked undercover in FBI counterintelligence, recruitment was often a long game. Today, spies can hide behind encrypted messaging, fake identities and the anonymity of the internet. But in the 1990s and early 2000s, foreign intelligence officers frequently had to get much closer to their targets.

Consider this old-school recruitment scenario:

A Russian military intelligence officer (GRU) operating under diplomatic cover identifies a government employee who likes to spend his lunch hours working through a few martinis at a Washington-area bar.

That typically makes for an interesting target. Maybe he has financial problems. Maybe his marriage is falling apart. Maybe he hates his boss, feels under appreciated or simply likes having someone listen to him. And old Russian spies can make excellent drinking buddies.

Nothing happens quickly. Lunch becomes a routine. Acquaintances become friends. Eventually the new friend asks for a small favor. Maybe the name of someone in the government he can contact about promoting trade or selling a product.

Harmless enough.

Then comes another favor. And then another.

Slowly, the government employee becomes accustomed to helping. Eventually one of those favors crosses a line and includes confidential information.

Now the relationship changes.

The friendly Russian drinking buddy has something much more valuable than the information itself: leverage. The target faces disgrace, termination or even prosecution if anyone discovers what he has done. Friendship can become recruitment, reinforced by the oldest combination in espionage: bribery and blackmail.

Keep helping me and I’ll make those financial problems disappear.

Stop helping me and perhaps someone learns what you’ve already done.

Carrot. Stick.

In the end, neither matters very much. What matters is that the target keeps trudging forward, one small step at a time, until turning around becomes very difficult.

The first favor isn’t necessarily about what the spy needs.

It’s about discovering what you’ll do.

Twenty-five years later, Russian intelligence appears to have updated the playbook. Forget the martinis. Forget months spent cultivating a friendship. According to a newly unsealed federal indictment, one alleged recruitment began with something much simpler:

Take some pictures. We’ll pay you about $200.

The $200 Recruitment

On September 15, federal prosecutors unsealed charges against five alleged members of a Russian intelligence-services network. All five defendants remain at large, and the allegations in the indictment have not been proven in court.

But the recruitment sequence described by prosecutors is fascinating because beneath all the modern technology is a very old intelligence operation.

The scheme allegedly began in Lituania in 2025 when a recruit was offered about $200 to conduct surveillance of a Russian dissident. Take photographs. Record video. Collect information. Then came the real offer:

We will pay you $25,000 to kill the person you have been watching.

When the recruit refused, the recruiter pivoted to other possibilities, including arson and attacks against substations and warehouses.

Then the intelligence operation appeared in the United States.

According to a DOJ indictment, a recruiter offered an operative between $1,000 and $1,500 to conduct surveillance against a prominent Russian dissident. The instructions were remarkably specific: use airplane mode, begin recording before reaching the target location, slow down near the house and later delete the chat.

The alleged offer eventually escalated to $40,000 to make the dissident “disappear.”

Fortunately, the FBI disrupted the U.S. operation before a murder could happen. Go FBI!

There is a broader counterintelligence lesson embedded here: The favor is the hook.

A small assignment can answer enormously important questions about a potential recruit.

  • Will this person follow instructions?

  • Will they keep a secret?

  • Will they collect information on another person without asking too many questions?

  • Will they conceal what they’re doing?

  • And, perhaps most importantly: Will they do it again?

Every completed assignment reels the target closer to the recruiters net.

Taking a photograph may not feel like espionage. Recording a route may not feel like surveillance. Moving a conversation onto an encrypted app may feel like privacy. Deleting the messages afterward may seem like a reasonable request from someone who values discretion.

But put those pieces together and you may be collecting someone’s pattern of life for people whose nefarious intentions are hard to understand.

That is why the $200 is so clever. Neither the money or the task was remarkable. The value is in the recruit’s willingness to take the first damning step.

The tools of espionage have changed dramatically since I hunted spies for the FBI. Recruitment can happen remotely. Surveillance can be outsourced. Encrypted communications allow recruiters and operatives to operate continents apart.

But human nature hasn’t received a software update.

Sure, the technology changed. The trap didn’t.

Tip of the Week

Become a Link Detective

This week, a friend invited me to a party. Or…someone using my friend’s email address did.

The invitation looked like it came from Punchbowl. Familiar graphics. A big Open Your Invitation button. The sender’s actual Gmail address.

Names have been changed to protect the innocent. Would eb cool if I had a friend named “John Smith” though.

I never click on links unless I’m damn certain they are safe. Good thing too because the button didn’t lead to Punchbowl.

It pointed to an unrelated domain ending in .cfd.

That was my cue to investigate—not RSVP.

I saved the original email and examined its headers: the routing and authentication information behind the message. It passed SPF, DKIM and DMARC, three checks designed to help detect forged senders. You can do this just as easily! I dropped the whole mess into ChatGPT and asked it to be my cyber sleuth.

Those checks supported that the message had come from my friend’s legitimate gmail account. However, they did not establish that my friend intended to send it, or that the invitation was safe.

The graphics supplied another clue. They were hosted by the real Punchbowl service, but the links attached to them led somewhere else. Stolen branding with a different destination.

What Can You Do?

Before opening an unexpected invitation, shared document or urgent request:

  1. Inspect the destination. On a computer, hover over the link without clicking. Read where it actually goes.

  2. Look for a mismatch. An invitation claiming to be from Punchbowl shouldn’t unexpectedly route you to an unrelated website. Don’t obsess over whether .com, .net or some other ending is inherently safe. Look for whether the destination makes sense.

  3. Use a robot friend. If your investigation makes you even a tiny bit concerned, throw the entire email into your favorite LLM (ChatGPT, Claude, Gemini, CoPilot, etc.) and ask the Chatbot to investigate.

  4. Verify through another channel. Call or text the sender using contact information you already have. Don’t rely on the suspicious message to authenticate itself.

  5. Don’t click to investigate. Curiosity is useful. Visiting the suspected trap isn’t.

  6. Warn the sender. If they didn’t send it, they should immediately review their account security, active sessions and connected applications. In this case I told my friend: “change your password and turn on Two-Factor authentication ASAP on your gmail account!”

You don’t need to become an email-forensics expert. You just need to notice when the story and the destination disagree.

Breach of the Week

The Government Email That Fooled a Bank

Here is another reason legitimate-looking credentials shouldn’t end an investigation.

British fintech company Revolut confirmed that it disclosed customer information to an unauthorized party after receiving fraudulent email requests that came from a legitimate government-agency email domain. Sound familiar? Are you seeing the theme today?

The government domain was real. The request wasn’t.

Potentially disclosed information included identity documents, verification selfies, account statements and transaction histories. The government agency involved and precise number of affected customers have not been publicly disclosed.

Consider this the institutional version of our Link Detective lesson. A legitimate email address proves where a message came from. It doesn’t prove the person using it has legitimate authority to make the request.

When sensitive information is at stake, verify both the authority and the purpose through a separate channel.

Whether it’s a spy asking for a photograph, a suspicious party invitation or a government request for financial records, the lesson is the same:

Don’t let the first sign of legitimacy become the last thing you verify.

From the Field

narrative

Continue the Mission

If you enjoyed this week’s newsletter, you’ll find even more inside my new book, SPIES, LIES, AND CYBERCRIME. Drawing on my years hunting spies for the FBI, it reveals how espionage, cybercrime, and AI-powered deception intersect—and what you can do to stay one step ahead.

Ready for the next mission?

Already read the book? A quick review on Amazon or Goodreads helps more readers discover it. Thank you for your support.

Please support my sponsors. It only takes a click - no purchase necessary!

Every headline satisfies an opinion. Except ours.

Remember when the news was about what happened, not how to feel about it? 1440's Daily Digest is bringing that back. Every morning, they sift through 100+ sources to deliver a concise, unbiased briefing — no pundits, no paywalls, no politics. Just the facts, all in five minutes. For free.

Know Someone Who’d Enjoy This?

If someone forwarded you this newsletter, join more than 4,500 readers every Tuesday for practical lessons from the worlds of espionage, cybercrime, artificial intelligence, and the human stories behind them.

Stay safe out there and keep thinking like a spy hunter.

Praemonitus Praemunitus!

Forewarned is Forearmed!

~Eric

Reply

Avatar

or to participate

Recommended for you

View all
caret-right